2 months ago
5e52cd6Plugin install/update downloaded the plugin files and the marketplace manifest in separate branch-ref fetches. GitHub caches those paths independently, so right after a push one fetch could see the new commit while the other served the previous one, failing the update with "Marketplace source hash mismatch" until the caches converged. Resolve the source ref to its commit SHA once per operation, download the plugin tree at that immutable commit, and read the same-repo marketplace manifest at it too (still parsed against the branch ref so plugin sourceInputs keep matching recorded install metadata). Any resolution failure falls back to the previous branch-ref behavior, and a hash mismatch that survives pinning now names the commit so a truly stale manifest is actionable. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parentab1ad55